Toggle light / dark theme

Over 100 Chrome Web Store extensions steal user accounts, data

More than 100 malicious extensions in the official Chrome Web Store are attempting to steal Google OAuth2 Bearer tokens, deploy backdoors, and carry out ad fraud.

Researchers at application security company Socket discovered that the malicious extensions are part of a coordinated campaign that uses the same command-and-control (C2) infrastructure.

The threat actor published the extensions under five distinct publisher identities in multiple categories: Telegram sidebar clients, slot machine and Keno games, YouTube and TikTok enhancers, a text translation tool, and utilities.

Elon Musk’s xAI sues over Colorado’s AI antidiscrimination law, claiming it’s a threat to Grok’s free speech

Senate Bill 205, passed in 2024, is one of the nation’s first attempts to regulate ‘high-risk’ AI systems and protect consumers from ‘algorithmic discrimination’ — or disparate treatment or impacts on protected classes under Colorado law.

In the complaint, which was filed in federal court in Denver, Musk’s lawyers contend that the law is ‘unconstitutionally vague’ and ‘invites arbitrary enforcement’ because it fails to define some key terms. They also contend that Colorado’s law would cause Musk’s AI chatbot, Grok, to ‘abandon its disinterested pursuit of truth and instead promote the State’s ideological views on various matters, racial justice in particular,’ which they say violates the First Amendment.

‘Unless the implementation and enforcement of SB24-205 is enjoined, it will violate xAI’s constitutional rights and cause irreparable constitutional harm, impose enormous burdens on xAI and the AI industry, and substitute Colorado’s political preferences for the national economic and security imperative of American AI dominance,’ the complaint reads in part…

…State Rep. Briana Titone, D-Arvada, one of Senate Bill 205’s lead sponsors, told The Sun that Musk’s lawsuit seems like a ‘fishing expedition’ that misinterprets the core of the law.

‘This is where the disconnect is. SB 205 is about consequential decisions, not about freedom of speech,’ Titone said. ‘It’s completely detached from it. And they’re trying to use this argument for a law that has nothing to do with what he’s saying. We’re not restricting speech. Our bill does not say that Grok still can’t be a dick.’


The lawsuit was filed at a time when the Trump administration looks to preempt state regulation of AI models through executive fiat.

Move Reveals Its New Markerless Motion Capture System Genesis

Move, a company focused on motion capture and 3D animation, unveiled Genesis, its new high-quality markerless motion capture system, delivering data quality “comparable to optical systems alongside the reliability, security, and integration required by professional VFX, AAA gaming, and creative studios.”

This is a “foundational strategic shift” from the consumer-focused Move Pro to a dedicated enterprise ecosystem. Genesis has already replaced Move Pro on the company’s site, replacing action cameras with Z-Cam integration.

Retinal Vessel Dysfunction in Cerebral Autosomal Dominant Arteriopathy With Subcortical Infarcts and Leukoencephalopathy

An Ultra-Widefield Fluorescein Angiography Study.


This website uses a security service to protect against malicious bots. This page is displayed while the website verifies you are not a bot.

After Anthropic’s Mythos AI uncovers thousands of zero-day bugs, top US officials huddle with bank CEOs

The heads of America’s biggest banks met this week with Federal Reserve Chairman Jerome Powell and Treasury Secretary Scott Bessent to weigh the security implications of a new artificial intelligence system developed by Anthropic, according to reports Friday.

The gathering was convened on the sidelines of an event in Washington, with officials calling the extra session to address Anthropic’s newly unveiled Claude Mythos model, Bloomberg and the Financial Times reported.

The US Treasury Department did not immediately respond to a request for comment. The Federal Reserve had no comment.

Microsoft: Canadian employees targeted in payroll pirate attacks

A financially motivated threat actor tracked as Storm-2755 is stealing Canadian employees’ salary payments after hijacking their accounts in payroll pirate attacks.

The attackers used malicious Microsoft 365 sign-in pages to steal victims’ authentication tokens and session cookies by redirecting them to domains (e.g., bluegraintours[.]com) hosting malicious web pages (pushed to the top of search engine results through malvertising or SEO poisoning) that masqueraded as Microsoft 365 sign-in forms.

This allowed Storm-2755 to bypass multifactor authentication (MFA) in adversary‑in‑the‑middle (AiTM) attacks by replaying stolen session tokens rather than re-authenticating.

Project Zomboid identifies and bans over a dozen Steam Workshop mods containing ‘heavily obfuscated code’ that was ‘creating malicious files’

The exploit only affected Build 42 branches of Project Zomboid (the game’s current ‘unstable’ testing release), so if you’re on Build 41, you were “not vulnerable to this specific issue,” the dev said. While The Indie Stone hasn’t determined what the malicious files were actually doing, “we strongly recommend that anyone who downloaded them take appropriate security measures to ensure their system is safe. Simply uninstalling the mods is not sufficient.”

If you use mods in Project Zomboid, check them against the list below to determine if you’ve downloaded and run any of these mods, which all look to be sound or music-related.

Hackers use pixel-large SVG trick to hide credit card stealer

A massive campaign impacting nearly 100 online stores using the Magento e-commerce platform hides credit card-stealing code in a pixel-sized Scalable Vector Graphics (SVG) image.

When clicking the checkout button, the victim is shown a convincing overlay that can validate card details and billing data.

The campaign was discovered by eCommerce security company Sansec, whose researchers believe that the attacker likely gained access by exploiting the PolyShell vulnerability disclosed in mid-March.

/* */